Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.3 HIGH
CVE-2026-53507 — oasdiff actions resolve external $refs by default, enabling SSRF and disclosure of struct…

oasdiff-action is a GitHub Action that detects breaking changes in OpenAPI specs and post a review on every pull request. Before version 0.0.51, the oasdiff actions resolved external $refs in the Ope…

Remote | Server-Side Request Forgery
Aug 31, 2026 Sep 09, 2026
Aug 31, 2026
Sep 09, 2026
6.5 MEDIUM
CVE-2026-14696 — Ethernet bridge RX packet leak enables denial of service via RX buffer-pool exhaustion

When Ethernet bridging is enabled (CONFIG_NET_ETHERNET_BRIDGE), eth_bridge_input_process() in subsys/net/l2/ethernet/bridge/bridge_input.c decides how each frame received on a bridge member interface…

zephyr zephyr | Denial of Service
Aug 31, 2026 Sep 01, 2026
Aug 31, 2026
Sep 01, 2026
5.4 MEDIUM
CVE-2026-14368 — Off-by-one out-of-bounds NUL write in Zephyr LwM2M JSON string parser

The LwM2M JSON content formatter's get_string() in subsys/net/lib/lwm2m/lwm2m_rw_json.c copies a parsed JSON string into a caller-supplied buffer and NUL-terminates it. The length guard used if (stri…

zephyr zephyr | Memory Corruption
Aug 31, 2026 Sep 01, 2026
Aug 31, 2026
Sep 01, 2026
3.1 LOW
CVE-2026-14367 — I3C IBI work-node free-list data race between ISR and workqueue thread

The I3C IBI subsystem in drivers/i3c/i3c_ibi_workq.c hands out statically-allocated work nodes through a free-list i3c_ibi_work_nodes_free implemented as a plain sys_slist_t, which provides no synchr…

zephyr zephyr | Race Condition
Aug 31, 2026 Sep 01, 2026
Aug 31, 2026
Sep 01, 2026
3.3 LOW
CVE-2023-31308 — AMD SMU Out-of-Bounds Read Denial of Service

A malicious virtual function can invoke the certain command handlers in the SMU, causing a denial of service due to out-of-bounds memory read.

| Memory Corruption
Aug 31, 2026 Sep 03, 2026
Aug 31, 2026
Sep 03, 2026
6.4 MEDIUM
CVE-2023-20511 — AMD Kernel Mode Driver Double Free Vulnerability

Release of an invalid pointer in the AMD kernel mode driver (KMD) could allow a privileged attacker to create a double free condition potentially leading to arbitrary code execution.

Remote | Memory Corruption
Aug 31, 2026 Sep 03, 2026
Aug 31, 2026
Sep 03, 2026
6.5 MEDIUM
CVE-2026-82817 — dibo-software diboot Tenant Administrator Management API admin access control

A vulnerability was found in dibo-software diboot 3.8.0. Affected by this issue is some unknown functionality of the file /admin/ of the component Tenant Administrator Management API. Performing a ma…

diboot | Remote | Authorization
Aug 31, 2026 Sep 02, 2026
Aug 31, 2026
Sep 02, 2026
6.5 MEDIUM
CVE-2026-82816 — dibo-software diboot AI Session Endpoint ai-session authorization

A vulnerability has been found in dibo-software diboot 3.8.0. Affected by this vulnerability is an unknown functionality of the file /api/ai-session/ of the component AI Session Endpoint. Such manipu…

diboot | Remote | Authorization
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
7.5 HIGH
CVE-2026-82815 — MegaEase EaseProbe Middleware server.go realIP access control

A flaw has been found in MegaEase EaseProbe up to 2.3.0. Affected is the function realIP of the file web/server.go of the component Middleware. This manipulation of the argument X-Forwarded-For/X-Rea…

easeprobe | Remote | Authorization
Aug 31, 2026 Sep 01, 2026
Aug 31, 2026
Sep 01, 2026
6.4 MEDIUM
CVE-2026-82813 — BEN Group TubeBuddy for YouTube Extension tubebuddymaster1.js TBGlobal.GetToken data auth…

A vulnerability was detected in BEN Group TubeBuddy for YouTube Extension up to 5.8.4 on Chrome. This impacts the function TBGlobal.GetToken of the file tubebuddymaster1.js. The manipulation of the a…

tubebuddy_for_youtube_extension | Remote | Authentication
Aug 31, 2026 Sep 01, 2026
Aug 31, 2026
Sep 01, 2026
6.4 MEDIUM
CVE-2026-82811 — Toggl OÜ Toggl Track Extension postMessage origin validation

A security vulnerability has been detected in Toggl OÜ Toggl Track Extension 4.11.16. This affects an unknown function of the component postMessage Handler. The manipulation leads to origin validatio…

toggl_track_extension | Remote | Misconfiguration
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
7.7 HIGH
CVE-2026-79750 — MCPHub authenticated horizontal IDOR: any non-admin user executes tools on other users' M…

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.30, MCPHub scopes…

mcphub | Remote | Authorization
Aug 31, 2026 Sep 08, 2026
Aug 31, 2026
Sep 08, 2026
7.6 HIGH
CVE-2026-79749 — MCPHub: SSRF Guard Bypass via IPv6 Transition Addresses in URL Validation

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.32, MCPHub's SSRF…

mcphub | Remote | Server-Side Request Forgery
Aug 31, 2026 Sep 08, 2026
Aug 31, 2026
Sep 08, 2026
9.9 CRITICAL
CVE-2026-79748 — MCPHub: Authenticated non-admin user achieves RCE via POST /api/servers (missing authoriz…

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 0.12.15, the POST /ap…

mcphub | Remote | Authorization
Aug 31, 2026 Sep 08, 2026
Aug 31, 2026
Sep 08, 2026
7.1 HIGH
CVE-2026-79747 — MCPHub vulnerable to SSRF: a non-admin user can make mcphub request arbitrary URLs and re…

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.32, an authentica…

mcphub | Remote | Server-Side Request Forgery
Aug 31, 2026 Sep 08, 2026
Aug 31, 2026
Sep 08, 2026
8.1 HIGH
CVE-2026-79746 — MCPHub: Server-scoped bearer key gains access to an entire group via partial (any-overlap…

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.31, when a bearer…

mcphub | Remote | Authorization
Aug 31, 2026 Sep 08, 2026
Aug 31, 2026
Sep 08, 2026
7.1 HIGH
CVE-2026-79745 — MCPHub: Missing Authorization on Built-in Prompt & Resource CRUD (Unauthorized Tampering …

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.32, the built-in …

mcphub | Remote | Authorization
Aug 31, 2026 Sep 08, 2026
Aug 31, 2026
Sep 08, 2026
8.8 HIGH
CVE-2026-79744 — MCPHub: Missing Authorization on `PUT /api/system-config` Lets Any Non-Admin Rewrite Glob…

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.29, MCPHub's PUT …

mcphub | Remote | Authorization
Aug 31, 2026 Sep 08, 2026
Aug 31, 2026
Sep 08, 2026
6.9 MEDIUM
CVE-2026-79743 — MCPHub: Path Traversal via Malicious MCPB Manifest Name

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 0.12.13, MCPB File Up…

mcphub | Remote | Path Traversal
Aug 31, 2026 Sep 08, 2026
Aug 31, 2026
Sep 08, 2026
9.1 CRITICAL
CVE-2026-51730 — TOTOLINK T6 Incorrect Access Control

Incorrect access control in the delWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi ACL rules via sending a crafted POST request to /cgi-bin…

Remote | Authorization
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
Showing 20 of 14946 Results